We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enable descriptions for statement nodes such as and and or.
and
or
For example:
- or: - string: Environment - string: windir - match: set registry value description: Modify %windir% environment variable
@re-fox has provided a use of case in: mandiant/capa-rules/pull/51
We need to come up with a way to render this in the -vv output. Suggestions:
-vv
- or: # Modify %windir% environment variable - string: Environment @ 0x401213 - string: windir @ 0x40121A
- or: = Modify %windir% environment variable - string: Environment @ 0x401213 - string: windir @ 0x40121A
- or: - string: Environment @ 0x401213 - string: windir @ 0x40121A description: Modify %windir% environment variable
I like option 2. What do you think? Any other ideas?
This also need to be added in capa explorer.
The text was updated successfully, but these errors were encountered:
yeah, i'm leaning towards 2 for consistency and keeping a dense representation of the information.
Sorry, something went wrong.
we'll need to add support in the json document, too
Ana06
Successfully merging a pull request may close this issue.
Summary
Enable descriptions for statement nodes such as
and
andor
.For example:
Motivation
@re-fox has provided a use of case in: mandiant/capa-rules/pull/51
Additional context
We need to come up with a way to render this in the
-vv
output. Suggestions:1 - Inline as a comment
2 - Inline with the already existent description symbol
3 - Not in line
I like option 2. What do you think? Any other ideas?
This also need to be added in capa explorer.
The text was updated successfully, but these errors were encountered: